Local-first codebase intelligence: cited answers, audits, reports. EN/FR.
Inferred from the transports this listing declares (stdio). A client not listed here hasn’t been ruled out — it just isn’t something Forge can confirm.
Verification confirms publisher identity (repo ownership), not code safety. The security scan covers known CVEs and suspicious install scripts.
Read out of the source npm actually ships, at scan time. The package was never executed. Tools registered dynamically at runtime, or hidden inside bundled or minified code, can be missed — so this is a floor on the tool surface, not a complete census of it.
codebase_intelligencePro technical audit: architecture, tech debt, opportunities and creative ideas.Pro technical audit: architecture, tech debt, opportunities and creative ideas.
No input schema was published for this tool.
codebase_reportStrategic board report with SWOT, scorecards and 90-day roadmap.Strategic board report with SWOT, scorecards and 90-day roadmap.
No input schema was published for this tool.
codebase_auditNon-conformities and technical-debt audit with concrete fixes.Non-conformities and technical-debt audit with concrete fixes.
No input schema was published for this tool.
codebase_tasksGenerate a prioritized TASKS.md with sprints and Before/After.Generate a prioritized TASKS.md with sprints and Before/After.
No input schema was published for this tool.
codebase_ceoOne-page executive brief with metrics, risks and killer moves.One-page executive brief with metrics, risks and killer moves.
No input schema was published for this tool.
codebase_playerUser journey and playthrough UX analysis.User journey and playthrough UX analysis.
No input schema was published for this tool.
codebase_searchSearch files and symbols by term or pattern.Search files and symbols by term or pattern.
No input schema was published for this tool.
codebase_explainExplain how a file or symbol works.Explain how a file or symbol works.
No input schema was published for this tool.
codebase_refactorPropose a refactor for a file or function.Propose a refactor for a file or function.
No input schema was published for this tool.
codebase_chatOpen Q/A on the codebase.Open Q/A on the codebase.
No input schema was published for this tool.
codebase_creaGenerate creative ideas, slogans or marketing concepts from the code.Generate creative ideas, slogans or marketing concepts from the code.
No input schema was published for this tool.
codebase_healthDeterministic static analysis: circular deps, dead code, duplication, complexity hotspots, health score. Returns findings directly — no LLM call.Deterministic static analysis: circular deps, dead code, duplication, complexity hotspots, health score. Returns findings directly — no LLM call.
No input schema was published for this tool.
codebase_impactBlast-radius analysis: which files transitively depend on a target file — what breaks if it changes. Deterministic, no LLM call.Blast-radius analysis: which files transitively depend on a target file — what breaks if it changes. Deterministic, no LLM call.
No input schema was published for this tool.
13 of 13 tools published a description.
Tool names and descriptions are written by the publisher and shown verbatim as inert text. They are the strings an MCP client passes to a model, so Forge scans them for prompt-injection patterns — any finding appears with the security scan above. “Privileged” is a keyword match on the tool name, not an audit of what the tool does: a benign-sounding name can still do anything.
Local-first codebase intelligence: cited answers, audits, reports. EN/FR.
Linked names open Forge’s index of every entry observed exposing that tool. Browse all indexed tools.
The crawl stopped at the 60-package limit. The rest of the tree was never resolved.
36 more resolved packages are not drawn here (display cap: 24). Every dependency carrying an advisory is drawn regardless of the cap. Full inventory (CycloneDX SBOM)
75 declared dependencies never landed in the tree. They are missing from Forge's resolution, not from the package.
+63 more not listed. The counts by reason above cover all of them.
Not followed: optionalDependencies, peerDependencies. This tree covers runtime dependencies only, so anything those pull in was never resolved.